DocFence 0.57.0 Tightens OOXML Signature Validation for Relationship Transforms
DocFence version 0.57.0 introduces stricter enforcement of how Relationship Transforms are declared within ECMA-376 Open Packaging Conventions package signatures. Prior to this release, a permitted Relationship Transform could appear in a same-document SignedInfo reference that was not a proper manifest relationship declaration, allowing malformed signatures to pass undetected. The update now immediately flags such misplaced transforms as malformed, along with selectorless transforms, missing or misordered canonicalization, incorrect content types, and duplicate transform declarations. The changes were validated against a 69-test suite and 29 public DOCX fixtures, with all 38 Relationship Transforms meeting the new boundary and public profiles remaining byte-identical to version 0.56. DocFence performs static structural checks only and does not execute transforms, verify signatures, or validate certificates.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in